Monday, August 1, 2016

Find member of based on job title

Here one I have no clue why I wrote it, in any event I thought I would share.  This script looks up all users with similar titles and documents every group they are a member of.  In environments where access is granted by a person’s job role this may come in handy to validate like job roles are in the same group, have the same access especially after adds/changes.

Start of script

Get-ADUser -filter { title -like "*Manager*" } | Select-Object samAccountName | foreach { (Get-ADUser $_.samAccountname –Properties MemberOf | Select-Object MemberOf).MemberOf | Out-File c:\temp\Member_of_Manager.txt }


End of script

Monday, July 25, 2016

Find all accounts that have their password set to never expire

This guy was written to address accounts that are in violation of policy.  Password set to never expire is an easy dig on an audit for auditors.  I run this every 90 days and investigate where needed.  Once the investigation is complete and all exceptions are approved any object leftover gets its password set to (PasswordNeverExpires -eq $False).

Get-ADUser -filter { Enabled -eq $True -and PasswordNeverExpires -eq $True } –Properties * |Select-Object Name, SAMAccountName, Title, Enabled, WhenCreated, WhenChanged, PasswordNeverExpires, Description | Export-Csv 'C:\temp\Pass_Never_Expires.csv' -NoTypeInformation –NoClobber


You can always run this as a scheduled task and email it to yourself.  That info can be found here: http://mytechnicalsolution.blogspot.com/search/label/send-MailMessage

Monday, July 18, 2016

Ping a list of servers

Ever get tired of being given a list of servers to do something with and more than a handful are offline or have been retired?  I am, so I decided to write this quickie to validate which machines are online and which are not.  Depending on the number of servers in your list this process can take a few to complete.

The script below will return just the machines that responded.

$Computers = Get-Content C:\temp\Servers_Names.txt; Test-Connection $Computers -ErrorAction SilentlyContinue -Count 1 | Select-Object Address,IPv4Address,ResponseTime,BufferSize

This one will provide the results to a text file.

$Computers = Get-Content C:\temp\Servers_Names.txt; Test-Connection $Computers | Out-File C:\temp\Ping_Results.txt

And alternatively this script will just provide a count of how many can ping and how many can’t.


$computers = Get-Content C:\temp\Servers_Names.txt; $Computers | group {test-connection -count 1 -ComputerName $_ -quiet} | Sort-Object Name -Descending


Example:
  Count Name                    Group                                                                                                                                                                                                                            
  -----      ----                         -----                                                                                                                                                                                                                            
  14        True                      {Server1, Server2Server3Serve...}                                                                                                                                                                                    
  4          False                     {Server15Server16Server17, Se...                                                                                                                                                                 

Monday, July 11, 2016

Finding all DNS servers in the domain

Learning a new environment is tough sometimes, not wanting to be the new guy asking all the questions.  One of the things I wrote to help me gather information without asking or giving me enough information to ask an intelligent question was the script below.  It was written specifically to find servers running the DNS service but can be modified easily to find any service running on windows servers in your domain.

Originally I wrote the script like this:

Get-ADComputer -Filter {OperatingSystem -Like "Windows *Server*"} -Property *  | foreach { Get-Service -name "DNS" -ComputerName $_.Name -ErrorAction SilentlyContinue | Select-Object -Property MachineName,ServiceName,Status }

But kept erroring out. Exact error:

Get-ADComputer : The server has returned the following error: invalid enumeration context. 

I googled some and found this: 


So I followed the script modification recommendations and ended up with this:

$adobjects = Get-ADComputer -Filter {OperatingSystem -Like "Windows *Server*"} -Property *; $adobjects = | foreach { Get-Service -name "DNS" -ComputerName $_.Name -ErrorAction SilentlyContinue | Select-Object -Property MachineName,ServiceName,Status } 

The script ran to completion without error.  If you want to export to CSV add this to the end of the script.

| Export-CSV "C:\temp\DNS_Servers.csv" -NoClobber -NoTypeInformation


Just so you know, depending on the number of server in your domain this script can take a while to complete, but it does complete.

Monday, July 4, 2016

Ensure all accounts in the Disabled Accounts OU are Disabled

I noticed the help desk was enabling accounts and leaving them in the disabled accounts OU.  We have user based policies that get applied based on your departmental OU.  By not moving the account to the correct departmental OU these policies don’t get applied.  Causes user issues like drive mappings and printer mappings don’t get applied.  After talking with the manager of the help desk who discussed it with their team nothing changed.  This laziness caused un-necessary calls to the help desk where the help desk technician manually mapped drives and printers.  This extra work circumvented our standard process and needed to be fixed so I wrote this.

This script runs multiple times a day and disables every account in the disabled accounts OU.  Once I put this in place and communicated this was happening and should be zero impact to our customers as long as the help desk preformed their job correctly my standards were now being followed.

Start of script

###############################################################################
#  Script Name:   Disable_User_Accounts_in_Disabled_Accounts_OU.ps1
#  Created On:    02/26/2014
#  Author:        Joshua
#  Purpose:       Ensure all accounts in the Disabled Accounts OU are Disabled                                               
#  Last Modified: 04/28/2016
#  Last Modifier: Joshua
###############################################################################

Get-ADUser -Filter 'name -like "*"' -SearchBase "OU=Disabled Accounts,DC=YourDomain,DC=com" | Disable-ADAccount


End of script

Sunday, July 3, 2016

Domain Replication Report

Years ago I would for a company that felt it needed a domain controller at every remote location against the advice of all of the employed SEs and SAs.  This caused some issues being that there were 90 domain controllers in the domain.  On an almost daily basis we had domain controllers go off line and start the 60 count down to tombstone.  So to make sure my co-workers were doing their job I wrote this to prevent a forced rip out of a tomb-stoned domain controller.  The original script was very simple only running RepAdmin.  Since then I have put in some additions like dcddiag.  It also will provide a list of machines that are currently in the computers container.  As you may know no group policies can be applied to these machines.  This was an addition so I could keep the helpdesk honest.  Hope this helps.

###############################################################################
#  Script Name:   Domain_Replication_Summary.ps1
#  Created On:    02/15/2009
#  Author:        Joshua & Matthew
#  Purpose:       Get Replication Summary and email to a group                                                     
#  Last Modified: 02/15/2016
#  Last Modifier: Joshua
###############################################################################


#Import-Modules
Import-Module ActiveDirectory
Add-PSSnapin Quest.ActiveRoles.ADManagement

#Variables
$date = Get-Date -Format yyyyMMdd
$aging = (Get-Date).adddays(-8).ToString("yyyyMMdd")
$aging2 = (Get-Date).adddays(-8).ToString("yyyyMMdd")
$log      = "C:\ST_Logs\Replication_Summary_Report_'$date'.txt"
$log2      = "C:\ST_Logs\DCDiag_Summary_Report_'$date'.txt"
$smtp = "YourSMTP.YourDomain.com"
$to = "Domain_Replication_Summary@ YourDomain.com "
$from = "DNR_Reports@ YourDomain.com "
$subject = "Domain Health Check $date"
$staging = dsquery computer "CN=Computers,DC=YourDomain,DC=com" -name *
$bodystart = "Please see attached logs.

Below computer accounts are in the Computers Container and need to be moved.
"
$body = $bodystart+$staging

# Run RepAdmin Commands
repadmin /replsummary | Out-File -FilePath $log
dcdiag /e /q /n:YourDomain.com | Out-File -FilePath $log2

# Remove all reports greater than 7 days old
Remove-Item "C:\PS_Scripts\Temp_Working\Replication_Summary_Reports\Replication_Summary_Report_'$aging'.txt" -recurse
Remove-Item "C:\PS_Scripts\Temp_Working\Replication_Summary_Reports\Replication_Summary_Report_'$aging2'.txt" -recurse
Remove-Item "C:\PS_Scripts\Temp_Working\Replication_Summary_Reports\DCDiag_Summary_Report_'$aging'.txt" -recurse
Remove-Item "C:\PS_Scripts\Temp_Working\Replication_Summary_Reports\DCDiag_Summary_Report_'$aging2'.txt" -recurse

#### Now send the email using \> Send-MailMessage

send-MailMessage -SmtpServer $smtp -To $to -From $from -Subject $subject -Body $body -BodyAsHtml -Priority normal -Attachments $log, $log2

Monitor MS Exchange

Years ago I needed a way to monitor Exchange.  When I say Exchange I mean all aspects of Exchange, total number of mail boxes, number of mailboxes per DB, DB size, DB white space, free space in the log drive, and last backup time. At the time I was doing a lot of this calculating manually until I found Steve Goodman's site http://www.stevieg.org/ and his PS1 “Get-ExchangeEnvironmentReport”.  This report is great, I have used it in every environment I have managed since 2009 at it has saved me countless hours of time not having to calculate everything in excel like I was in 2009.  If an MS Exchange report that provides a quick high level status of your mail cluster, then check out this report.